Cyber-attacks and a state’s right to self-defence
Imagine a hostile cyber operation that disables Bangladesh’s cyber infrastructure, kills the electricity grids, takes digital payment gateways offline, paralyses critical healthcare facilities and shuts down communications across the country. Essential services grind to a halt, human lives are at stake, and the economy is hanging on by a thread. Could Bangladesh consider such an operation to have fallen under the definition of an ‘armed attack’ and invoke its right of self-defence under Article 51 of the United Nations (UN) Charter?
Article 51 of the UN Charter recognises the inherent right of self-defence ‘if an armed attack occurs’ against a UN member state. This provision was drafted in 1945, when the concept of armed attack was restricted to the periphery of bombs, bullets, invading armies and physical warfare. Naturally, the bare text of Article 51 fails to encompass the 21st-century threat of cyberattacks.
This debate is especially important for states such as Bangladesh, where the disruption of interconnected financial, energy, healthcare and communications systems could have consequences far exceeding the physical condition of the computers involved. International law should therefore measure cyber harm not merely by what happens to machines, but by what the loss of their functionality does to people.
The International Court of Justice (ICJ) established an important distinction in the Nicaragua v United States of America case. It held that armed attacks were the most grave forms of the use of force, distinguishable from less grave uses of force according to their scale and effects. Consequently, not every unlawful use of force permits a forcible response in self-defence. Although the requisite gravity serves as a de-escalating factor, a metric developed based on physical violence falls short of encapsulating the threat posed by cyber operations.
Contrarily, there is a scholarly opinion that the legal character of a cyber operation should depend substantially on its consequences instead of the technological instruments used. For example, Michael Schmitt’s foundational study of computer-network attacks proposed assessing cyber operations through factors such as severity, immediacy, directness, invasiveness, measurability, military character and state involvement. This effects-based approach was developed further in the Tallinn Manual 2.0 (‘Manual’), which was prepared by an international group of independent experts. The Manual maintains that a cyber operation may amount to a use of force where its scale and effects are comparable to those produced by conventional force. It similarly treats the scale and effects of an operation as central to determining whether the higher armed-attack threshold has been crossed.
The easiest cases are cyber operations causing death, injury or physical destruction. Malware that causes a power plant to explode, aircraft to crash or machinery to destroy itself may produce effects indistinguishable from a kinetic attack. For instance, Stuxnet, which physically damaged centrifuges at Iran’s Natanz nuclear facility, became an important illustration of how computer code can generate tangible destructive consequences. However, experts reportedly differed on whether the incident crossed the armed-attack threshold, demonstrating the uncertainty surrounding the applicable standard. A more difficult category involves severe functional disruption without physical destruction. A cyber operation might render a hospital network, electricity grid, or banking system unusable while leaving every computer and building physically intact.
Authors like Oona Hathaway argue that the law of war presently governs only a small proportion of cyber operations. Most malicious cyber activity consequently remains outside the Charter’s exceptional self-defence framework. François Delerue similarly concludes that cyber operations can, in certain circumstances, amount to a use of force or an armed attack, although most state-sponsored cyber operations remain below these thresholds. States have also begun developing their own interpretations. France accepts that a cyberattack may constitute an armed attack where its scale and severity are comparable to physical force. Its position allows consideration of substantial loss of life and considerable physical or economic damage, assessed according to the circumstances of each case.
In my opinion, the better approach is neither to require physical destruction in every case nor to classify every major economic loss as an armed attack. The first approach is technologically outdated, as disabling critical infrastructure may be as damaging as destroying it. The second is dangerously expansive because it could permit military responses to every cybercrime, espionage or economic coercion.
Thus, the ICJ should instead recognise a confined principle of functional equivalence. A cyber operation should qualify as an armed attack where it renders essential infrastructure substantially unusable, and its consequences are comparable to those of a grave kinetic attack. Relevant considerations should include the essential nature of the affected system, the duration and geographical reach of the disruption, its reversibility, the population affected, and the foreseeable danger to life, health or fundamental governmental functions.
In the same vein, attribution must nevertheless remain a strict safeguard. A victim state must connect a cyber operation to another state through the rules governing state organs, agents or supported non-state actors before using force against that state in self-defence.
This debate is especially important for states such as Bangladesh, where the disruption of interconnected financial, energy, healthcare and communications systems could have consequences far exceeding the physical condition of the computers involved. International law should therefore measure cyber harm not merely by what happens to machines, but by what the loss of their functionality does to people.
The writer is a student of law, University of Dhaka.
Comments